CVE-2025-48912 – Apache Superset SQL Injection Vulnerability
The following table lists the changes that have been made to the CVE-2025-48912 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] May. 30, 2025 Action […]
CVE-2025-48334 – BinaryCarpenter Woo Slider Pro Missing Authorization Vulnerability
The following table lists the changes that have been made to the CVE-2025-48334 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] May. 30, 2025 Action […]
CVE-2025-5236 – NinjaTeam Chat for Telegram WordPress Stored Cross-Site Scripting
CVE ID : CVE-2025-5236 Published : May 30, 2025, 8:15 a.m. | 1 hour, 3 minutes ago Description : The NinjaTeam Chat for Telegram plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘username’ parameter in all versions up to, and including, 1.1 due to insufficient input sanitization and output escaping. This makes it possible […]
CVE-2025-4431 – Unsplash WordPress Plugin Missing Capability Check Allows Unauthorized Data Modification
CVE ID : CVE-2025-4431 Published : May 30, 2025, 8:15 a.m. | 1 hour, 3 minutes ago Description : The Featured Image Plus – Quick & Bulk Edit with Unsplash plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the fip_save_attach_featured function in all versions up to, and including, […]
CVE-2025-4943 – LA-Studio Element Kit for Elementor Stored Cross-Site Scripting Vulnerability
CVE ID : CVE-2025-4943 Published : May 30, 2025, 7:15 a.m. | 2 hours, 3 minutes ago Description : The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘data-lakit-element-link’ parameter in all versions up to, and including, 1.5.2 due to insufficient input sanitization and output escaping. This makes it […]
CVE-2025-48880 – FreeScout Race Condition Vulnerability
The following table lists the changes that have been made to the CVE-2025-48880 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] May. 30, 2025 Action […]
CVE-2025-48875 – FreeScout Cross-Site Scripting (XSS) Vulnerability
The following table lists the changes that have been made to the CVE-2025-48875 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] May. 30, 2025 Action […]
CVE-2025-48936 – Zitadel Host Header Injection Vulnerability
Zitadel is open-source identity infrastructure software. Prior to versions 2.70.12, 2.71.10, and 3.2.2, a potential vulnerability exists in the password reset mechanism. ZITADEL utilizes the Forwarded or X-Forwarded-Host header from incoming requests to construct the URL for the password reset confirmation link. This link, containing a secret code, is then emailed to the user. If […]
CVE-2025-48865 – Fabio HTTP Hop-by-Hop Header Manipulation Vulnerability
The following table lists the changes that have been made to the CVE-2025-48865 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] May. 30, 2025 Action […]
CVE-2025-48492 – GetSimple CMS Remote Code Execution (RCE) Vulnerability
The following table lists the changes that have been made to the CVE-2025-48492 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] May. 30, 2025 Action […]